HOW-TO: Disable USB Storage Devices

IT infrastructure engineers install firewalls to protect the intra-net from outside. Mail filters on SMTP servers are there to protect users from SPAM. Anti-virus software are deployed to further boost protection on the workstation itself. Regardless of whatever software or hardware is put in place, it serves to beef up security.

One of the many open portals or backdoors that may compromise the infrastructure as a whole is the USB port. Why?.. because USB portable storage devices are probably the next best thing since sliced bread in the storage world -- portable, handly, concealable, you name it. As many as its advantages are its disadvantages. To secure the infrastructure, the access to the USB port needs to be restricted. But how?

A year ago 1GB seemed to be a lot, but 2GB is even frowned upon now. This topic is a bit old.. But still the threat is out there in the open. And the issue is still a hot topic for debate. There is a lengthy instruction on how this can be done but there is no concrete solution that permanently works. Even microsoft has published a lengthy procedure that outlines how this is done.

The procedure outlined in the microsoft KB article, suggests the denial of permissions on the two files responsible for the installation of drivers and services for USB storage functionality.

%SystemRoot%\Inf\Usbstor.pnf
%SystemRoot%\Inf\Usbstor.inf

The deny permission is important especially if the users are non-administrators. The mentioned files could also be renamed, but it needs to be noted so that the procedure can be reversed if need be.

Aside from the above, the registry needs to be checked for this key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR

The value for the data key "Start" should be set to 4 (or Disabled) from 3 (or Automatic). The value determines whether the driver is loaded or not when Windows starts. A reboot will be required after the changes.

But for a person who wants a click and go solution, one may want to try another utility to achieve the same purpose. You may download the utility from the author's website.



The click and go solution can also quickly reverse the procedure to enable USB storage devices. The only thing it cannot do is work around the required reboot.

Tighter security always sacrifices functionality. As usual, the goal is to strike a balance between the two. But when it comes to the balance and trade-offs, it is always a grey area.

You might also be interested in:

Feedback

We at pimp-my-rig strive to keep on improving, help us reach that goal by leaving comments or constructive criticisms. Don't miss out on our next feature -- subscribe via RSS (What is RSS?).

Share This

0 comments: